01Introduction
TL;DR — We collect the minimum we need to scan your listings. Nothing sold or shared.
ListingSafe is committed to protecting your privacy. This policy explains what we collect, how we use it, and what we never do with your data.
02Information we collect
- Listing data you submit (title, description, tags) for scanning
- IP address — used for rate limiting on free scans
- Google account information (email address, account ID) when you sign in with Google
- Email address — only if you use the "Email Report" feature to receive your scan results or appeal letter. We use it to send the requested report and may occasionally send product update notices. Email preferences live in your Settings — replying to one of these emails does not reach us, so use Settings or the unsubscribe link in the email itself.
- When you scan from the browser extension, a short label naming which Etsy page layout the scanner recognised — so we can tell a page redesign apart from a listing that simply has no vintage details.
- When you scan from your own listing edit page in Etsy Shop Manager, we also record a short description of the form fields on that page — each text field's HTML tag, id, name and CSS class, and the first 80 characters of what you have typed in it (at most 8 fields). This is what lets us repair the scanner when Etsy redesigns the page; without it a scan that silently reads the wrong field is invisible to us. We never collect the page's HTML, and nothing outside those fields.
- If you connect your Etsy shop, we store the access and refresh tokens Etsy issues to us, your shop id and shop name, and the listings, reviews and shop details we read from Etsy on your behalf. Etsy content is deleted on the schedule in section 05.
- Your listing text is sent to Google Gemini to produce the compliance verdict, the rewrite and the appeal letter.
- If you use Copycat Watch or the single-image check, the photos you select are sent to a reverse-image search provider — SerpApi or SearchApi, depending on which one this installation is configured to use — and to Google Cloud Vision, to look for other pages using the same image. Nothing is sent until you start a check.
- When a listing mentions a brand, we look that brand name up in a USPTO trademark database through RapidAPI to build the registration evidence card. Only the brand name goes out — not your title, description or tags.
- Email we send you — the scan report, the appeal letter, and the scheduled-scan digests — is delivered by Resend. Resend receives your email address and the contents of that email.
- The free scan on our home page is protected by Cloudflare Turnstile, a bot check. Cloudflare receives your IP address and the technical details a browser sends with any request, so it can tell a person apart from a script. It runs on the home page only.
- Every page loads its typefaces from Google Fonts and its stylesheet from the Tailwind CDN. Your browser fetches those files directly, so both receive your IP address and the technical details a browser sends with any request — before you interact with anything. They receive nothing else: no listing text, no photos, no account details.
- Every page also loads Google Analytics from googletagmanager.com, so we can see how many people use the site and which parts they use. Google receives your IP address, the pages you open, your browser and device details, and the page that sent you here; on the Copycat pages it also receives a few product events — that a scan finished and how many results it had, and the domain of a match you act on. It does not receive your listing text, your photos, your email address, or your account details. To recognise a returning visit it stores a randomly generated identifier in cookies in your browser.
- Every page that can start a checkout — the home page and the app — loads Paddle's checkout script from cdn.paddle.com as the page opens, before you click anything. Paddle receives your IP address and the technical details a browser sends with any request, and sets one cookie of its own (
__cf_bm, Cloudflare's bot check for Paddle's own network). It receives nothing else until you actually start a purchase: no listing text, no photos, no account details. - Cookies. Google Analytics sets the cookies described above. We set two of our own: one that keeps you signed in, and one that records which link first brought you here — it lasts 30 days and tells us which channels sellers arrive from. Neither of ours carries your listing data. Paddle sets the
__cf_bmcookie described above on the pages that load its script.
03How we use it
- To perform compliance scans on your listings
- To enforce usage limits per plan
- We never sell your data, and we never use it to train AI models. To run the checks you ask for, we pass the data above to the service providers named in section 02 (Google Gemini, SerpApi or SearchApi for reverse image search, Google Cloud Vision, RapidAPI for the trademark lookup, Resend for the email we send you, Cloudflare for the bot check, Google Fonts and the Tailwind CDN for the page's own fonts and stylesheet, Google Analytics for usage statistics, Paddle for payment) — and to no one else.
04Payment
Payments are processed by Paddle. We do not store your payment details.
05Data retention
Scan results are kept in your browser (localStorage) so you can revisit them.
On our servers we keep: the listing text you scanned (title, description, tags) together with the scan's result, so we can check our own accuracy and fix wrong verdicts; and, for extension scans from an edit page, the field description above. Listing text is never used to train AI models, sold, or shared. Cached scan results expire after 7 days.
06Contact
Questions about this policy? Email [email protected] — usually a reply within 24h.